Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:3552-1

Опубликовано: 08 окт. 2024
Источник: suse-cvrf

Описание

Security update for pgadmin4

This update for pgadmin4 fixes the following issues:

  • CVE-2024-4216: Fixed XSS in /settings/store endpoint (bsc#1223868)

Список пакетов

SUSE Linux Enterprise Module for Python 3 15 SP6
pgadmin4-4.30-150300.3.15.1
pgadmin4-doc-4.30-150300.3.15.1
pgadmin4-web-4.30-150300.3.15.1
SUSE Linux Enterprise Module for Server Applications 15 SP5
pgadmin4-4.30-150300.3.15.1
pgadmin4-doc-4.30-150300.3.15.1
pgadmin4-web-4.30-150300.3.15.1
openSUSE Leap 15.5
pgadmin4-4.30-150300.3.15.1
pgadmin4-doc-4.30-150300.3.15.1
pgadmin4-web-4.30-150300.3.15.1
pgadmin4-web-uwsgi-4.30-150300.3.15.1

Описание

pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.


Затронутые продукты
SUSE Linux Enterprise Module for Python 3 15 SP6:pgadmin4-4.30-150300.3.15.1
SUSE Linux Enterprise Module for Python 3 15 SP6:pgadmin4-doc-4.30-150300.3.15.1
SUSE Linux Enterprise Module for Python 3 15 SP6:pgadmin4-web-4.30-150300.3.15.1
SUSE Linux Enterprise Module for Server Applications 15 SP5:pgadmin4-4.30-150300.3.15.1

Ссылки